Cyber Briefing: 2026.07.29
Active zero-day exploitation, massive consumer-facing scams, and recurring enterprise breaches highlight severe operational and financial vulnerabilities across critical infrastructure, retail...
Welcome to Cyber Briefing, your daily source for all things cybersecurity. We bring you the latest advisories, alerts, incidents, and news every weekday.
Critical edge infrastructure faces urgent exposure as CISA adds severe vulnerabilities in Arista VeloCloud Orchestrator and Fortinet FortiOS to its Known Exploited Vulnerabilities catalog, triggering strict patching deadlines for federal agencies to prevent remote command execution and sensitive data access. Meanwhile, consumer risk has surged via a large-scale phishing scam using over 120 impersonated Walmart domains to steal full payment card credentials using fake liquor sales, while Frontier Airlines deals with reputational damage following its third major data incident within a single year.
From a business and regulatory standpoint, the cost of systemic compromise continues to escalate, with IBM reporting that global average data breach costs have climbed to $4.99 million—heavily driven by AI-powered attacks and extortion tactics centered on public reputation. In response to these expanding threats, governments and standards bodies are tightening frameworks; the US and Australia jointly issued strategic guidance for isolating critical operational technology (OT) systems, while CREST introduced a formal accreditation module to govern the ethical implementation of AI in penetration testing.
Listen to our podcast here ⏬
⚡THREAT LANDSCAPE
CISA adds Arista and Fortinet flaws to KEV catalog
CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: a critical command injection flaw in Arista VeloCloud Orchestrator (CVE-2026-16812, CVSS 10.0) and an information disclosure issue in Fortinet FortiOS (CVE-2025-68686, CVSS 5.3). The Arista vulnerability allows remote attackers to execute commands on on-premises orchestrator systems, while the Fortinet flaw enables attackers who have already compromised a device to bypass security protections and access sensitive data. Federal agencies must patch the Arista flaw by July 20, 2026, and the Fortinet issue by August 10, 2026, with private organizations also urged to prioritize remediation. Read More
120 fake Walmart stores stealing credit cards
Over 120 fake websites impersonating Walmart are stealing credit card information from shoppers by offering heavily discounted liquor (40-70% off) and directing victims to fraudulent checkout pages. The scam sites use identical WordPress/WooCommerce templates with Walmart branding and request full payment card details including CVV codes. Anyone who entered card information on these domains should immediately contact their card issuer to cancel the card and monitor for unauthorized charges. Read More
🚨INCIDENTS & REAL-WORLD IMPACT
Frontier Airlines Hit by Third Data Breach
Frontier Airlines has reportedly experienced its third data security incident in 2024, following a June breach disclosed by a researcher called BobDaHacker who published findings about boarding pass vulnerabilities. The airline has now faced multiple security failures within a single year, raising concerns about its data protection practices. Customers should monitor accounts for unauthorized activity and consider changing passwords if they have interacted with Frontier’s systems recently. Read More
🔓 EXECUTIVE RISK & CYBERNOMICS
IBM: Average Data Breach Cost Hits $5M
IBM’s 2026 Cost of a Data Breach Report reveals the average breach cost has reached $4.99 million, a 12% increase from the previous year, based on analysis of 602 organizations breached between March 2025 and February 2026. Healthcare remains the most expensive sector at $6.6 million per breach for the 13th consecutive year, while AI-driven attacks now account for over 25% of incidents and add an average of $1 million to breach costs. Organizations face mounting losses from business disruption, customer trust erosion, and attackers increasingly using reputation damage threats rather than just encryption to extort payments. Read More
🛡️ POLICY, REGULATION & LEGAL SIGNALS
US, Australia Release OT Isolation Guidance
The United States and Australia have jointly released guidance for critical infrastructure operators on isolating operational technology (OT) systems. The document provides steps for separating vital OT and supporting systems from broader networks and maintaining isolated operations for extended periods. This guidance aims to help organizations protect industrial control systems from cyber threats by implementing network segmentation strategies. Read More
💻 CAREER ENABLEMENT
CREST Launches AI-Enabled Pentesting Accreditation
CREST, a cybersecurity industry body, has launched an optional AI-Enabled Penetration Testing accreditation module for service providers who use AI in their operations and client services. The new standard, unveiled July 28, allows accredited providers to undergo independent assessment demonstrating responsible AI governance, addressing a market gap where AI adoption has outpaced oversight. Applications are now open for existing CREST members, with the first accreditations expected within a month. Read More
Copyright © 2026 CyberMaterial. All Rights Reserved.
Follow CyberMaterial on:
Substack, LinkedIn, Twitter, Reddit, Instagram, Facebook, YouTube, and Medium








